Cross Domain Local Storage
cross_domain_local_storage
Vendor: Cross Domain Local Storage Project • 4 CVEs
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cross Domain Local Storage Project 1Cross Domain Local Storage Nov 21, 2024 Apr 7, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. There...Show more |
1Cross Domain Local Storage Project 1Cross Domain Local Storage Nov 21, 2024 Apr 7, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent obj...Show more |
1Cross Domain Local Storage Project 1Cross Domain Local Storage Nov 21, 2024 Apr 7, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load...Show more |
1Cross Domain Local Storage Project 1Cross Domain Local Storage Nov 21, 2024 Apr 7, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attackers who can entice a...Show more |